Latest CVE Feed
-
4.8
MEDIUMCVE-2025-5125
The Custom Post Carousels with Owl WordPress plugin before 1.4.12 uses the featherlight library and makes use of the data-featherlight attribute without sanitizing before using it.... Read more
Affected Products : custom_post_carousels_with_owl- Published: Jun. 20, 2025
- Modified: Jul. 11, 2025
- Vuln Type: Misconfiguration
-
9.8
CRITICALCVE-2025-6310
A vulnerability, which was classified as critical, has been found in PHPGurukul Emergency Ambulance Hiring Portal 1.0. Affected by this issue is some unknown functionality of the file /index.php. The manipulation of the argument Message leads to sql injec... Read more
Affected Products : emergency_ambulance_hiring_portal- Published: Jun. 20, 2025
- Modified: Jun. 26, 2025
- Vuln Type: Injection
-
8.8
HIGHCVE-2025-6309
A vulnerability classified as critical was found in PHPGurukul Emergency Ambulance Hiring Portal 1.0. Affected by this vulnerability is an unknown functionality of the file /admin/add-ambulance.php. The manipulation of the argument ambregnum leads to sql ... Read more
Affected Products : emergency_ambulance_hiring_portal- Published: Jun. 20, 2025
- Modified: Jun. 26, 2025
- Vuln Type: Injection
-
8.8
HIGHCVE-2025-6308
A vulnerability classified as critical has been found in PHPGurukul Emergency Ambulance Hiring Portal 1.0. Affected is an unknown function of the file /admin/bwdates-request-report-details.php. The manipulation of the argument fromdate/todate leads to sql... Read more
Affected Products : emergency_ambulance_hiring_portal- Published: Jun. 20, 2025
- Modified: Jun. 26, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2025-6307
A vulnerability was found in code-projects Online Shoe Store 1.0. It has been rated as critical. This issue affects some unknown processing of the file /function/edit_customer.php. The manipulation of the argument firstname leads to sql injection. The att... Read more
Affected Products : online_shoe_store- Published: Jun. 20, 2025
- Modified: Jun. 26, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2025-6306
A vulnerability was found in code-projects Online Shoe Store 1.0. It has been declared as critical. This vulnerability affects unknown code of the file /admin/admin_index.php. The manipulation of the argument Username leads to sql injection. The attack ca... Read more
Affected Products : online_shoe_store- Published: Jun. 20, 2025
- Modified: Jun. 26, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2025-6305
A vulnerability was found in code-projects Online Shoe Store 1.0. It has been classified as critical. This affects an unknown part of the file /admin/admin_feature.php. The manipulation of the argument product_code leads to sql injection. It is possible t... Read more
Affected Products : online_shoe_store- Published: Jun. 20, 2025
- Modified: Jun. 26, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2025-6304
A vulnerability was found in code-projects Online Shoe Store 1.0 and classified as critical. Affected by this issue is some unknown functionality of the file /cart.php. The manipulation of the argument qty[] leads to sql injection. The attack may be launc... Read more
Affected Products : online_shoe_store- Published: Jun. 20, 2025
- Modified: Jun. 26, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2025-6303
A vulnerability has been found in code-projects Online Shoe Store 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /contactus1.php. The manipulation of the argument Message leads to sql injection. The ... Read more
Affected Products : online_shoe_store- Published: Jun. 20, 2025
- Modified: Jun. 26, 2025
- Vuln Type: Injection
-
9.0
HIGHCVE-2025-6302
A vulnerability, which was classified as critical, was found in TOTOLINK EX1200T 4.1.2cu.5232_B20210713. Affected is the function setStaticDhcpConfig of the file /cgi-bin/cstecgi.cgi. The manipulation of the argument Comment leads to stack-based buffer ov... Read more
- Published: Jun. 20, 2025
- Modified: Jul. 02, 2025
- Vuln Type: Memory Corruption
-
5.4
MEDIUMCVE-2025-6301
A vulnerability, which was classified as problematic, has been found in PHPGurukul Notice Board System 1.0. This issue affects some unknown processing of the file /admin/manage-notices.php of the component Add Notice. The manipulation of the argument Titl... Read more
- Published: Jun. 20, 2025
- Modified: Jun. 26, 2025
- Vuln Type: Cross-Site Scripting
-
9.8
CRITICALCVE-2025-6300
A vulnerability classified as critical was found in PHPGurukul Employee Record Management System 1.3. This vulnerability affects unknown code of the file /admin/editempeducation.php. The manipulation of the argument yopgra leads to sql injection. The atta... Read more
Affected Products : employee_record_management_system- Published: Jun. 20, 2025
- Modified: Jun. 26, 2025
- Vuln Type: Injection
-
5.8
MEDIUMCVE-2025-6299
A vulnerability classified as critical has been found in TOTOLINK N150RT 3.4.0-B20190525. This affects an unknown part of the file /boa/formWSC. The manipulation of the argument targetAPSsid leads to os command injection. It is possible to initiate the at... Read more
- Published: Jun. 20, 2025
- Modified: Jul. 02, 2025
- Vuln Type: Injection
-
5.5
MEDIUMCVE-2025-6264
Velociraptor allows collection of VQL queries packaged into Artifacts from endpoints. These artifacts can be used to do anything and usually run with elevated permissions. To limit access to some dangerous artifact, Velociraptor allows for those to requi... Read more
Affected Products : velociraptor- Published: Jun. 20, 2025
- Modified: Jun. 23, 2025
- Vuln Type: Authorization
-
9.8
CRITICALCVE-2025-6296
A vulnerability was found in code-projects Hostel Management System 1.0. It has been rated as critical. Affected by this issue is some unknown functionality of the file /empty_rooms.php. The manipulation of the argument search_box leads to sql injection. ... Read more
- Published: Jun. 20, 2025
- Modified: Jul. 02, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2025-6295
A vulnerability was found in code-projects Hostel Management System 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file /allocated_rooms.php. The manipulation of the argument search_box leads to sq... Read more
- Published: Jun. 20, 2025
- Modified: Jun. 26, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2025-6294
A vulnerability was found in code-projects Hostel Management System 1.0. It has been classified as critical. Affected is an unknown function of the file /contact.php. The manipulation of the argument hostel_name leads to sql injection. It is possible to l... Read more
- Published: Jun. 20, 2025
- Modified: Jun. 26, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2025-6293
A vulnerability was found in code-projects Hostel Management System 1.0 and classified as critical. This issue affects some unknown processing of the file /contact_manager.php. The manipulation of the argument student_roll_no leads to sql injection. The a... Read more
- Published: Jun. 20, 2025
- Modified: Jun. 26, 2025
- Vuln Type: Injection
-
9.0
HIGHCVE-2025-6292
A vulnerability has been found in D-Link DIR-825 2.03 and classified as critical. This vulnerability affects the function sub_4091AC of the component HTTP POST Request Handler. The manipulation leads to stack-based buffer overflow. The attack can be initi... Read more
- Published: Jun. 20, 2025
- Modified: Jun. 26, 2025
- Vuln Type: Memory Corruption
-
9.0
HIGHCVE-2025-6291
A vulnerability, which was classified as critical, was found in D-Link DIR-825 2.03. This affects the function do_file of the component HTTP POST Request Handler. The manipulation leads to stack-based buffer overflow. It is possible to initiate the attack... Read more
- Published: Jun. 20, 2025
- Modified: Jun. 26, 2025
- Vuln Type: Memory Corruption